Vulnerability in PeopleSoft Enterprise HCM Shared Components by Oracle
CVE-2018-2878
6.1MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 April 2018
Summary
A vulnerability exists in the PeopleSoft Enterprise HCM Shared Components of Oracle's PeopleSoft Products, particularly impacting the Notepad subcomponent. This flaw can be easily exploited by an unauthenticated attacker with network access via HTTP. Successful exploitation requires human interaction from a third-party user, and while the vulnerability lies within the HCM Shared Components, it poses risks to additional products as well. Attackers leveraging this vulnerability may gain unauthorized rights to update, insert, or delete data within the compromised components, as well as access a range of sensitive data without permission.
Affected Version(s)
PeopleSoft Enterprise HCM Shared Components 9.2
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved